CVE-2023-53116: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid potential UAF in nvmet_req_complete() An nvme target ->queue_response() operation implementation may free the request passed as argument. Such implementation potentially could result in a use after free of the request pointer when percpu_ref_put() is called in nvmet_req_complete(). Avoid such problem by using a local variable to save the sq pointer before calling __nvmet_req_complete(), thus avoiding dereferencing the req pointer after that function call.

Affected products

  • Linux Linux Kernel: from 4.8, before 4.14.311 (fixed in 4.14.311); from 4.15, before 4.19.279 (fixed in 4.19.279); from 4.20, before 5.4.238 (fixed in 5.4.238); from 5.5, before 5.10.176 (fixed in 5.10.176); from 5.11, before 5.15.104 (fixed in 5.15.104); from 5.16, before 6.1.21 (fixed in 6.1.21); …

Published 2025-05-02. Last modified 2026-08-04.